sync
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read and follow instructions from an external file located at
node_modules/@notionhq/apps/skills/sync/SKILL.md. This creates a surface where instructions from a project dependency are ingested into the agent context. - Ingestion points: The local file system path
node_modules/@notionhq/apps/skills/sync/SKILL.md. - Boundary markers: None are defined in the skill body to delimit or sanitize the external instructions.
- Capability inventory: The skill itself does not define any tools, subprocess calls, or network operations.
- Sanitization: No sanitization or validation of the external file's content is performed.
- [NO_CODE]: The skill consists exclusively of markdown instructions and metadata. It does not include any scripts, binaries, or executable code, relying instead on existing project dependencies.
Audit Metadata